GrayAlpha is a financially motivated cyber threat cluster with significant operational overlap with FIN7 and is widely assessed as either a FIN7 sub-cluster or close affiliate rather than a wholly distinct actor. The activity associated with GrayAlpha aligns with the broader FIN7 ecosystem’s long-running cybercrime operations, including malware delivery, social engineering, and post-compromise access intended to support monetization. GrayAlpha has been observed using shared infrastructure, tooling, and tradecraft consistent with FIN7, including continued reliance on hosting and network resources historically associated with that ecosystem. GrayAlpha is known for web-based malware delivery campaigns that abuse user trust in routine software acquisition and update workflows. Observed infection vectors include fake browser update pages, counterfeit software download sites impersonating legitimate utilities, and traffic distribution systems used to funnel victims to malicious payload delivery chains. These campaigns have impersonated a range of well-known products and services to increase credibility and drive user execution. A hallmark of GrayAlpha activity is the use of custom loaders to stage remote access malware. Reported tooling includes PowerNet, a PowerShell-based loader that decompresses and executes NetSupport RAT, and MaskBat, an obfuscated loader with similarities to FakeBat. GrayAlpha has also been linked to delivery of FireClient malware in campaigns involving fraudulent browser-extension or software-update lures. The group’s tradecraft emphasizes layered delivery, obfuscation, and flexible initial access mechanisms rather than a single static malware family. The actor has been observed operating multiple concurrent infection chains at the same time, suggesting a mature and adaptable intrusion capability. Techniques associated with GrayAlpha include fake update and download lures, traffic redirection through distribution systems, staged payload execution through custom loaders, and use of legitimate remote administration software for follow-on access. This approach is consistent with FIN7’s historical pattern of blending bespoke malware development with socially engineered delivery and evasive execution methods. GrayAlpha is not generally described as a nation-state actor. Available reporting instead places it in the financially motivated cybercriminal sphere, closely tied to FIN7, one of the most prolific and technically sophisticated e-crime groups active since at least 2013. FIN7 has historically targeted sectors such as retail, hospitality, and finance, and GrayAlpha appears to represent a more recent operational cluster within or adjacent to that broader criminal apparatus. Known aliases include GrayAlpha and GrayAlpha (FIN7).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GrayAlpha (FIN7) is a financially motivated threat group known for sophisticated malware campaigns, including fake browser extensions and malvertising to deliver backdoors like FireClient.
Threat cluster overlapping with FIN7; observed relying on Stark Industries infrastructure through mid-2025.
Financially motivated malware distribution and social engineering operations using fake browser/software update lures and TDS-based delivery; suspected use of custom PowerShell loaders (PowerNet, MaskBat) to deploy NetSupport RAT; focuses on information theft and network compromise.
Cybercrime group known for financially motivated attacks, recently observed with new infrastructure for ongoing operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.